• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

virusword.com

Learn Wordpress

  • Home
  • WordPress Shop
    • Fotopress
    • SEO Tool Kit
    • Social Contact
    • Tag Machine 2
    • Video Profits
  • Latest News
  • WordPress
    • Plugins
    • Themes
    • Tutorials
    • Videos
    • Woocommerce
  • About Us
  • Contact Us
    • Terms of Service
    • Privacy Policy
  • Show Search
Hide Search
Home/Woocommerce/WordPress Vulnerability Report — December 11, 2024

WordPress Vulnerability Report — December 11, 2024

In this report, 231 vulnerabilities have been publicly disclosed. Security patches for 134 of these plugins and themes are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 97 plugin and theme vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

window[“8adaf693_ce8a_4824_b682_b4b8390f4df7”] = {“blockId”:”8adaf693-ce8a-4824-b682-b4b8390f4df7″,”type”:”warning”,”content”:”

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.”,”className”:””};

Along with poor user account security, vulnerable plugins and themes are among the top reasons why WordPress websites get hacked. Unfortunately, cyberattacks are increasing in volume and sophistication. They’re also increasingly aimed at small to mid-sized businesses.

window[“5ae4c661_bb98_4654_994c_911b7c959dc7”] = {“blockId”:”5ae4c661-bb98-4654-994c-911b7c959dc7″,”className”:””,”isOpen”:true};

Table of Contents

  1. 1. WordPress Core
  2. 2. WordPress Plugins — 156 Patched / 179 Unpatched
    1. 2.1
      WP Mega Menu
    2. 2.2
      WPCargo Track & Trace
    3. 2.3
      Awesome Support – WordPress HelpDesk & Support Plugin
    4. 2.4
      Axeptio – Cookie Banner – GDPR Consent & Compliance with a friendly touch
    5. 2.5
      Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress
    6. 2.6
      EazyDocs – Most Powerful Knowledge base, wiki, Documentation Builder Plugin
    7. 2.7
      News Ticker for Elementor
    8. 2.8
      WP Menu Image
    9. 2.9
      Smaily for WP
    10. 2.10
      SQL Chart Builder
    11. 2.11
      Job Board Manager
    12. 2.12
      SIP Calculator
    13. 2.13
      LDD Directory Lite
    14. 2.14
      The Permalinker
    15. 2.15
      Nias course | ???? ??? ????
    16. 2.16
      Role Includer
    17. 2.17
      Radius Blocks – WordPress Gutenberg Blocks
    18. 2.18
      WordPress HelpDesk & Support Ticket System Plugin – Octrace Support
    19. 2.19
      WP Cookies Enabler
    20. 2.20
      Advanced Blog Post Block
    21. 2.21
      Poll, Poll Forms – WordPress Poll plugin by Poll Builder
    22. 2.22
      Woocommerce Blocks – Woolook
    23. 2.23
      WP-NERD Toolkit
    24. 2.24
      3D Avatar User Profile
    25. 2.25
      Add image to Post
    26. 2.26
      Advance Menu Manager
    27. 2.27
      Advanced Data Table For Elementor
    28. 2.28
      Advanced Fancybox
    29. 2.29
      Advanced What should we write next about
    30. 2.30
      AI Post Generator | AutoWriter
    31. 2.31
      Zita Site Builder
    32. 2.32
      Amazon Product Price
    33. 2.33
      Animated Counters
    34. 2.34
      Aphorismus
    35. 2.35
      AppMaps
    36. 2.36
      Appsplate
    37. 2.37
      Arabic Webfonts
    38. 2.38
      Arena.IM – Live Blogging for real-time events
    39. 2.39
      Arena.IM – Live Blogging for real-time events
    40. 2.40
      Firebase OTP Authentication
    41. 2.41
      Banner System
    42. 2.42
      Bet sport Free
    43. 2.43
      Better WP Login Page
    44. 2.44
      Bootstrap Buttons
    45. 2.45
      Buk
    46. 2.46
      Caldera SMTP Mailer
    47. 2.47
      Mollie for Contact Form 7
    48. 2.48
      ??????
    49. 2.49
      CK and SyntaxHighlighter
    50. 2.50
      Code Generator Pro
    51. 2.51
      Comments On Feed
    52. 2.52
      Companion Portfolio
    53. 2.53
      Connatix Video Embed
    54. 2.54
      CoSchool LMS
    55. 2.55
      Crafthemes Demo Import
    56. 2.56
      Cricket Live Score
    57. 2.57
      Critical Site Intel
    58. 2.58
      CRUDLab Google Plus Button
    59. 2.59
      CSV to html
    60. 2.60
      Custom Skins Contact Form 7
    61. 2.61
      Ultimate Endpoints With Rest Api
    62. 2.62
      Mimoos
    63. 2.63
      Display Future Posts
    64. 2.64
      Dr Affiliate
    65. 2.65
      DTC Documents
    66. 2.66
      Easy Site Importer
    67. 2.67
      ECT Product Carousel
    68. 2.68
      ECT Social Share
    69. 2.69
      EELV Newsletter
    70. 2.70
      Mandrill WP
    71. 2.71
      eTemplates
    72. 2.72
      Evernote Sync
    73. 2.73
      Feedpress Generator
    74. 2.74
      Flaming Forms
    75. 2.75
      Flash News / Post (Responsive)
    76. 2.76
      Floating Video Player
    77. 2.77
      Gaxx Keywords
    78. 2.78
      Geoportail Shortcode
    79. 2.79
      Get Post Content Shortcode
    80. 2.80
      GitSync
    81. 2.81
      glomex oEmbed
    82. 2.82
      Go Animate
    83. 2.83
      Grid Plus
    84. 2.84
      Gutensee
    85. 2.85
      Opt-In Downloads
    86. 2.86
      Hello In All Languages
    87. 2.87
      Horizontal scroll image slideshow
    88. 2.88
      HostFact bestelformulier integratie
    89. 2.89
      HQ Rental Software
    90. 2.90
      IDer Login
    91. 2.91
      Image Mapper
    92. 2.92
      Increase Sociability
    93. 2.93
      Insertify
    94. 2.94
      Instant Appointment
    95. 2.95
      jCarousel
    96. 2.96
      Jet Footer Code
    97. 2.97
      KH Easy User Settings
    98. 2.98
      Kredeum NFTs
    99. 2.99
      kvCORE IDX
    100. 2.100
      LaunchPage.app Importer
    101. 2.101
      Leader
    102. 2.102
      LeaderBoard Plugin
    103. 2.103
      Library Management System
    104. 2.104
      Like in Vk.com
    105. 2.105
      Category of Posts
    106. 2.106
      ListApp Mobile Manager
    107. 2.107
      LionScripts: Site Maintenance & Noindex Nofollow Plugin
    108. 2.108
      MDC Comment Toolbar
    109. 2.109
      Metrika
    110. 2.110
      Minterpress
    111. 2.111
      Multiple Admin Emails
    112. 2.112
      My IDX Home Search
    113. 2.113
      addWeather
    114. 2.114
      Nabz Image Gallery
    115. 2.115
      Navayan CSV Export
    116. 2.116
      Newsletter Subscriptions
    117. 2.117
      Onlywire Multi Autosubmitter
    118. 2.118
      Order Delivery & Pickup Location Date Time
    119. 2.119
      phZoom
    120. 2.120
      PixProof
    121. 2.121
      Popup Surveys & Polls for WordPress (Mare.io)
    122. 2.122
      Portfolio – Filterable Masonry Portfolio Gallery for Professionals
    123. 2.123
      Post Carousel & Slider
    124. 2.124
      Posts and Products Views for WooCommerce
    125. 2.125
      Posts Date Ranges
    126. 2.126
      PowerFormBuilder
    127. 2.127
      Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart
    128. 2.128
      Quietly Insights
    129. 2.129
      Share Buttons – Social Media
    130. 2.130
      Saksh Escrow System
    131. 2.131
      Saoshyant Element
    132. 2.132
      SeedProd Pro
    133. 2.133
      SeedProd Pro
    134. 2.134
      SeedProd Pro
    135. 2.135
      Service
    136. 2.136
      Sign In With Google
    137. 2.137
      Simple Booking Widget
    138. 2.138
      Slope Widgets
    139. 2.139
      Social Media Sharing
    140. 2.140
      SOPA Blackout
    141. 2.141
      WP Simple Pay Lite Manager
    142. 2.142
      Surbma | SalesAutopilot Shortcode
    143. 2.143
      SVG Shortcode
    144. 2.144
      TagGator
    145. 2.145
      TCBD Popover
    146. 2.146
      Tidy Up
    147. 2.147
      TPG Get Posts
    148. 2.148
      TSB Occasion Editor
    149. 2.149
      Ui Slider Filter By Price
    150. 2.150
      Utech World Time
    151. 2.151
      vBSSO-lite
    152. 2.152
      Visual Recent Posts
    153. 2.153
      Visualmodo Elements
    154. 2.154
      Website Toolbox Community
    155. 2.155
      WooCommerce Cart Count Shortcode
    156. 2.156
      WooCommerce Basic Ordernumbers
    157. 2.157
      WordPress Filter
    158. 2.158
      Wovax IDX
    159. 2.159
      WP-Ban-User
    160. 2.160
      WP Fiddle
    161. 2.161
      WP Flipkart Importer
    162. 2.162
      WP-HideThat
    163. 2.163
      Wp Login with Ajax
    164. 2.164
      WP Controller
    165. 2.165
      Wp NssUser Register
    166. 2.166
      Wp photo text slider 50
    167. 2.167
      WP Service Payment Form With Authorize.net
    168. 2.168
      Tithe.ly Giving Button
    169. 2.169
      WP?????
    170. 2.170
      WPBookit
    171. 2.171
      Admin Customization
    172. 2.172
      Wr Age Verification
    173. 2.173
      Wr Age Verification
    174. 2.174
      XML Multilanguage Sitemap Generator
    175. 2.175
      XPD Reduce Image Filesize
    176. 2.176
      YDS Support Ticket System
    177. 2.177
      States Map US
    178. 2.178
      YooBar
    179. 2.179
      Youtube Video Grid
    180. 2.180
      WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
    181. 2.181
      MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites
    182. 2.182
      Ninja Forms – The Contact Form Builder That Grows With You
    183. 2.183
      The Events Calendar
    184. 2.184
      User Role Editor
    185. 2.185
      Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
    186. 2.186
      Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
    187. 2.187
      SiteOrigin Widgets Bundle
    188. 2.188
      Gutenberg Blocks with AI by Kadence WP – Page Builder Features
    189. 2.189
      Members – Membership & User Role Editor Plugin
    190. 2.190
      Popup Builder – Create highly converting, mobile friendly marketing popups.
    191. 2.191
      Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
    192. 2.192
      Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
    193. 2.193
      Beaver Builder – WordPress Page Builder
    194. 2.194
      Image Widget
    195. 2.195
      LuckyWP Table of Contents
    196. 2.196
      Web Stories
    197. 2.197
      LearnPress – WordPress LMS Plugin
    198. 2.198
      LearnPress – WordPress LMS Plugin
    199. 2.199
      AI Engine
    200. 2.200
      Ajax Search Lite – Live Search & Filter
    201. 2.201
      Bold Page Builder
    202. 2.202
      Calculated Fields Form
    203. 2.203
      Easy Digital Downloads – eCommerce Payments and Subscriptions made easy
    204. 2.204
      Ultimate Blocks – WordPress Blocks Plugin
    205. 2.205
      Greenshift – animation and page builder blocks
    206. 2.206
      ?????? ????? ??????? Persian WooCommerce SMS
    207. 2.207
      FULL – Cliente
    208. 2.208
      NotificationX – Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating Notification Top Bar
    209. 2.209
      PPWP – Password Protect Pages
    210. 2.210
      New User Approve
    211. 2.211
      Rate My Post – Star Rating Plugin by FeedbackWP
    212. 2.212
      Minify HTML
    213. 2.213
      s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions
    214. 2.214
      Simple Side Tab
    215. 2.215
      Essential Real Estate
    216. 2.216
      Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie Consent
    217. 2.217
      MyParcel
    218. 2.218
      Events Addon for Elementor
    219. 2.219
      PowerPack Lite for Beaver Builder
    220. 2.220
      Primary Addon for Elementor
    221. 2.221
      Notibar – Notification Bar for WordPress
    222. 2.222
      Notibar – Notification Bar for WordPress
    223. 2.223
      Vimeography: Vimeo Video Gallery WordPress Plugin
    224. 2.224
      OAuth Single Sign On – SSO (OAuth Client)
    225. 2.225
      Coupon Affiliates – Affiliate Plugin for WooCommerce
    226. 2.226
      WPMobile.App — Android and iOS Mobile Application
    227. 2.227
      ElementsReady Addons for Elementor
    228. 2.228
      EventPrime – Events Calendar, Bookings and Tickets
    229. 2.229
      GEO my WP
    230. 2.230
      MStore API – Create Native Android & iOS Apps On The Cloud
    231. 2.231
      WP Crowdfunding
    232. 2.232
      WP Crowdfunding
    233. 2.233
      Hash Form – Drag & Drop Form Builder
    234. 2.234
      Cognito Forms
    235. 2.235
      Falcon – WordPress Optimizations & Tweaks
    236. 2.236
      Online Booking & Scheduling Calendar for WordPress by vcita
    237. 2.237
      Active Products Tables for WooCommerce. Use constructor to create tables 
    238. 2.238
      Responsive Filterable Portfolio
    239. 2.239
      Restaurant & Cafe Addon for Elementor
    240. 2.240
      Restrict – membership, site, content and user access restrictions for WordPress
    241. 2.241
      Simple Link Directory
    242. 2.242
      WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin
    243. 2.243
      360 Javascript Viewer
    244. 2.244
      Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader.
    245. 2.245
      FormFacade – WordPress plugin for Google Forms
    246. 2.246
      ForumWP – Forum & Discussion Board
    247. 2.247
      ImageRecycle pdf & image compression
    248. 2.248
      Memberful – Membership Plugin
    249. 2.249
      Posti Shipping
    250. 2.250
      Simple Restrict
    251. 2.251
      RapidLoad – Optimize Web Vitals Automatically
    252. 2.252
      NiceJob
    253. 2.253
      Property Hive Mortgage Calculator
    254. 2.254
      Property Hive Stamp Duty Calculator
    255. 2.255
      WPC Order Notes for WooCommerce
    256. 2.256
      Quran multilanguage Text & Audio
    257. 2.257
      Waymark
    258. 2.258
      WP Pipes
    259. 2.259
      AR for WordPress
    260. 2.260
      Car Dealer (Dealership) and Vehicle sales
    261. 2.261
      Device Detector
    262. 2.262
      Last Viewed Posts by WPBeginner
    263. 2.263
      Out of the Block: OpenStreetMap
    264. 2.264
      AIcomments – ??????????? ? ?????? ChatGPT
    265. 2.265
      CM Answers – Powerful WordPress Forum Plugin
    266. 2.266
      Cryptocurrency Price Widget
    267. 2.267
      iChart – Easy Charts and Graphs
    268. 2.268
      Mark New Posts
    269. 2.269
      WP Email Log – PostBox
    270. 2.270
      Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate
    271. 2.271
      Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate
    272. 2.272
      Themify Store Locator
    273. 2.273
      WooCommerce Additional Fees On Checkout (Free)
    274. 2.274
      Gutenberg Blocks and Page Layouts – Attire Blocks
    275. 2.275
      Projectopia – WordPress Project Management
    276. 2.276
      Payment Gateway Per Product for WooCommerce
    277. 2.277
      Check Pincode For Woocommerce
    278. 2.278
      Currency Converter Widget ? PRO
    279. 2.279
      NewsmanApp
    280. 2.280
      Print Science Designer
    281. 2.281
      Stop Registration Spam
    282. 2.282
      WP BASE Booking of Appointments, Services and Events
    283. 2.283
      WP Mailster
    284. 2.284
      AutoWP – AI Content Writer & Rewriter
    285. 2.285
      Booking System Trafft
    286. 2.286
      dejure.org Vernetzungsfunktion
    287. 2.287
      Email Reminders
    288. 2.288
      J&T Express Malaysia
    289. 2.289
      Revi.io – Customer & Products Reviews
    290. 2.290
      WordPress Post Grid Layouts with Pagination – Sogrid
    291. 2.291
      WordPress Post Grid Layouts with Pagination – Sogrid
    292. 2.292
      Staggs – Product Configurator Toolkit
    293. 2.293
      Lifetime free Drag & Drop Contact Form Builder for WordPress VForm
    294. 2.294
      Video & Photo Gallery for Ultimate Member
    295. 2.295
      Gou Manage My Account Menu – User Roles
    296. 2.296
      ICDSoft Reseller Store
    297. 2.297
      Ksher
    298. 2.298
      Media Downloader
    299. 2.299
      CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout
    300. 2.300
      Invoice Payment for WooCommerce
    301. 2.301
      Seraphinite Bulk Discounts for WooCommerce
    302. 2.302
      Hurrakify
    303. 2.303
      SMS for WooCommerce
    304. 2.304
      Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress
    305. 2.305
      Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress
    306. 2.306
      AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot
    307. 2.307
      LabelGrid Tools
    308. 2.308
      Simple Payment
    309. 2.309
      CarDealerPress
    310. 2.310
      CE21 Suite
    311. 2.311
      EduAdmin Booking
    312. 2.312
      Hack-Info
    313. 2.313
      FloristPress – Customize your Woo store for your Florist
    314. 2.314
      CleverNode Related Content
    315. 2.315
      Connect Contact Form 7 to Constant Contact V3
    316. 2.316
      Fancy Roller Scroller
    317. 2.317
      I Plant A Tree
    318. 2.318
      ImmoToolBox Connect
    319. 2.319
      Newsletter, Email Marketing, Email Subscriber – Mail Picker
    320. 2.320
      Simple Presenter
    321. 2.321
      SMSify
    322. 2.322
      UNIVERSAM
    323. 2.323
      WP Currency Exchange Rates
    324. 2.324
      WP Quick Shop
    325. 2.325
      DX Dark Site
    326. 2.326
      FooGallery Premium
    327. 2.327
      GeoFlickr
    328. 2.328
      Hello Event Widgets For Elementor
    329. 2.329
      WP SuperBackup
    330. 2.330
      Kundgenerator
    331. 2.331
      Quran Phrases About Most People Shortcodes
    332. 2.332
      Responsive Google Maps | by imbaa
    333. 2.333
      Termin-Kalender
    334. 2.334
      WooCommerce PDF Vouchers
    335. 2.335
      WP All Import Pro
  3. 3. WordPress Themes — 8 Patched / 2 Unpatched
    1. 3.1
      Olivia
    2. 3.2
      Zerif Lite
    3. 3.3
      Barter
    4. 3.4
      Bicycleshop
    5. 3.5
      Brand
    6. 3.6
      hmd
    7. 3.7
      Plain Post
    8. 3.8
      Avada
    9. 3.9
      Woffice
    10. 3.10
      WoodMart

window[“ed3338e2_9837_4a5f_8863_6cb34907bb1b”] = {“blockId”:”ed3338e2-9837-4a5f-8863-6cb34907bb1b”,”type”:”notice”,”content”:”

Our WordPress Vulnerability Report\u00a0covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of\u00a0Low,\u00a0Medium,\u00a0High, or\u00a0Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress \u2014 and the web \u2014 more secure.”,”className”:””};

Our WordPress Vulnerability Report covers the latest emerging WordPress plugin, theme, and core vulnerabilities. Each vulnerability will have a severity rating of Low, Medium, High, or Critical. Responsible disclosure of vulnerabilities is essential to keeping the WordPress community safe. Please share this report to help spread the word and make WordPress — and the web — more secure.

WordPress Core

WordPress 6.7.1 is available! This minor release features 16 bug fixes throughout Core and the Block Editor.

window[“f9d8667e_1be8_4596_a96c_488ad6b6a29d”] = {“blockId”:”f9d8667e-1be8-4596-a96c-488ad6b6a29d”,”text”:”No new core vulnerabilities were disclosed this week.”,”className”:””};

No new core vulnerabilities were disclosed this week.

WordPress Plugins — 128 Patched / 94 Unpatched

140+ Widgets | Xpro Addons For Elementor – FREE

Plugin:

140+ Widgets | Xpro Addons For Elementor – FREE

Plugin Slug:
xpro-elementor-addons

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54253

The vulnerability has not been patched. You should deactivate the plugin.

s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions

Plugin:

s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions

Plugin Slug:
s2member

Installations
10,000+

Vulnerability:
Remote Code Execution (RCE)

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-51815

The vulnerability has not been patched. You should deactivate the plugin.

Login Widget With Shortcode

Plugin:

Login Widget With Shortcode

Plugin Slug:
login-sidebar-widget

Installations
8,000+

Vulnerability:
Open Redirection

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54255

The vulnerability has not been patched. You should deactivate the plugin.

WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts

Plugin:

WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts

Plugin Slug:
wedevs-project-manager

Installations
8,000+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-12015

The vulnerability has not been patched. You should deactivate the plugin.

Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg

Plugin:

Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg

Plugin Slug:
borderless

Installations
7,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54211

The vulnerability has not been patched. You should deactivate the plugin.

Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )

Plugin:

Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library )

Plugin Slug:
magical-addons-for-elementor

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54212

The vulnerability has not been patched. You should deactivate the plugin.

Pinpoint Booking System – #1 WordPress Booking Plugin

Plugin:

Pinpoint Booking System – #1 WordPress Booking Plugin

Plugin Slug:
booking-system

Installations
4,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54252

The vulnerability has not been patched. You should deactivate the plugin.

Minimum and Maximum Quantity for WooCommerce

Plugin:

Minimum and Maximum Quantity for WooCommerce

Plugin Slug:
min-and-max-quantity-for-woocommerce

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54227

The vulnerability has not been patched. You should deactivate the plugin.

Message Filter for Contact Form 7

Plugin:

Message Filter for Contact Form 7

Plugin Slug:
cf7-message-filter

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-12027

The vulnerability has not been patched. You should deactivate the plugin.

News Kit Elementor Addons

Plugin:

News Kit Elementor Addons

Plugin Slug:
news-kit-elementor-addons

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54260

The vulnerability has not been patched. You should deactivate the plugin.

WordPress Page Builder – Zion Builder

Plugin:

WordPress Page Builder – Zion Builder

Plugin Slug:
zionbuilder

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54213

The vulnerability has not been patched. You should deactivate the plugin.

ForumWP – Forum & Discussion Board

Plugin:

ForumWP – Forum & Discussion Board

Plugin Slug:
forumwp

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-10879

The vulnerability has not been patched. You should deactivate the plugin.

Friends

Plugin:

Friends

Plugin Slug:
friends

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-12028

The vulnerability has not been patched. You should deactivate the plugin.

DELUCKS SEO

Plugin:

DELUCKS SEO

Plugin Slug:
delucks-seo

Installations
600+

Vulnerability:
Arbitrary File Download

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54259

The vulnerability has not been patched. You should deactivate the plugin.

RRAddons for Elementor

Plugin:

RRAddons for Elementor

Plugin Slug:
rrdevs-for-elementor

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54232

The vulnerability has not been patched. You should deactivate the plugin.

Import Export For WooCommerce

Plugin:

Import Export For WooCommerce

Plugin Slug:
import-export-for-woocommerce

Installations
200+

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54262

The vulnerability has not been patched. You should deactivate the plugin.

Shiptimize for WooCommerce

Plugin:

Shiptimize for WooCommerce

Plugin Slug:
shiptimize-for-woocommerce

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54235

The vulnerability has not been patched. You should deactivate the plugin.

Limit Login Attempts (Spam Protection)

Plugin:

Limit Login Attempts (Spam Protection)

Plugin Slug:
wp-limit-failed-login-attempts

Installations
200+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54234

The vulnerability has not been patched. You should deactivate the plugin.

Comfino Payment Gateway

Plugin:

Comfino Payment Gateway

Plugin Slug:
comfino-payment-gateway

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-11329

The vulnerability has not been patched. You should deactivate the plugin.

Designer – Addons for Elementor

Plugin:

Designer – Addons for Elementor

Plugin Slug:
designer

Installations
100+

Vulnerability:
Local File Inclusion

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54225

The vulnerability has not been patched. You should deactivate the plugin.

Prodigy Commerce

Plugin:

Prodigy Commerce

Plugin Slug:
prodigy-commerce

Installations
100+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54251

The vulnerability has not been patched. You should deactivate the plugin.

Clients

Plugin:

Clients

Plugin Slug:
clients

Installations
80+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54245

The vulnerability has not been patched. You should deactivate the plugin.

Elite Notification – Sales Popup, Social Proof, FOMO & WooCommerce Notification

Plugin:

Elite Notification – Sales Popup, Social Proof, FOMO & WooCommerce Notification

Plugin Slug:
elite-notification

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54241

The vulnerability has not been patched. You should deactivate the plugin.

Simple Notification

Plugin:

Simple Notification

Plugin Slug:
simple-notification

Installations
50+

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54242

The vulnerability has not been patched. You should deactivate the plugin.

Ni WooCommerce Order Export

Plugin:

Ni WooCommerce Order Export

Plugin Slug:
ni-woocommerce-order-export

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54231

The vulnerability has not been patched. You should deactivate the plugin.

Awesome Shortcodes

Plugin:

Awesome Shortcodes

Plugin Slug:
awesome-shortcodes

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54209

The vulnerability has not been patched. You should deactivate the plugin.

Blaze Online eParcel for WooCommerce

Plugin:

Blaze Online eParcel for WooCommerce

Plugin Slug:
blaze-online-eparcel-for-woocommerce

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54240

The vulnerability has not been patched. You should deactivate the plugin.

Board Document Manager from CHUHPL

Plugin:

Board Document Manager from CHUHPL

Plugin Slug:
board-document-manager-from-chuhpl

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54238

The vulnerability has not been patched. You should deactivate the plugin.

Easy Replace

Plugin:

Easy Replace

Plugin Slug:
easy-replace

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54244

The vulnerability has not been patched. You should deactivate the plugin.

Ni CRM Lead

Plugin:

Ni CRM Lead

Plugin Slug:
ni-crm-lead

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54237

The vulnerability has not been patched. You should deactivate the plugin.

Ni CRM Lead

Plugin:

Ni CRM Lead

Plugin Slug:
ni-crm-lead

Installations
10+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54258

The vulnerability has not been patched. You should deactivate the plugin.

Ni WooCommerce Bulk Product Editor

Plugin:

Ni WooCommerce Bulk Product Editor

Plugin Slug:
ni-woocommerce-product-editor

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54236

The vulnerability has not been patched. You should deactivate the plugin.

TAX SERVICE Electronic HDM

Plugin:

TAX SERVICE Electronic HDM

Plugin Slug:
virtual-hdm-for-taxservice-am

Installations
10+

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54261

The vulnerability has not been patched. You should deactivate the plugin.

ABCBiz Addons and Templates for Elementor

Plugin:

ABCBiz Addons and Templates for Elementor

Plugin Slug:
abcbiz-addons

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54247

The vulnerability has not been patched. You should deactivate the plugin.

Advanced Control Manager for WordPress by ItalyStrap

Plugin:

Advanced Control Manager for WordPress by ItalyStrap

Plugin Slug:
advanced-control-manager

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54233

The vulnerability has not been patched. You should deactivate the plugin.

Advanced Options Editor

Plugin:

Advanced Options Editor

Plugin Slug:
advanced-options-editor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54249

The vulnerability has not been patched. You should deactivate the plugin.

AI Quiz

Plugin:

AI Quiz

Plugin Slug:
ai-quiz

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-11323

The vulnerability has not been patched. You should deactivate the plugin.

AIO Contact

Plugin:

AIO Contact

Plugin Slug:
aio-contact

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54218

The vulnerability has not been patched. You should deactivate the plugin.

AIO Contact

Plugin:

AIO Contact

Plugin Slug:
aio-contact

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54219

The vulnerability has not been patched. You should deactivate the plugin.

Pulsating Chat Button

Plugin:

Pulsating Chat Button

Plugin Slug:
amin-chat-button

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-11813

The vulnerability has not been patched. You should deactivate the plugin.

ARForms

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
Path Traversal

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54216

The vulnerability has not been patched. You should deactivate the plugin.

ARForms

Plugin:

ARForms

Plugin Slug:
arforms

Vulnerability:
Settings Change

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54217

The vulnerability has not been patched. You should deactivate the plugin.

Authors List

Plugin:

Authors List

Plugin Slug:
authors-list

Vulnerability:
Arbitrary Code Execution

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-10952

The vulnerability has not been patched. You should deactivate the plugin.

Beautiful Taxonomy Filters

Plugin:

Beautiful Taxonomy Filters

Plugin Slug:
beautiful-taxonomy-filters

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-12270

The vulnerability has not been patched. You should deactivate the plugin.

Block Controller

Plugin:

Block Controller

Plugin Slug:
block-controller

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54208

The vulnerability has not been patched. You should deactivate the plugin.

BP Profile Shortcodes Extra

Plugin:

BP Profile Shortcodes Extra

Plugin Slug:
bp-profile-shortcodes-extra

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-11732

The vulnerability has not been patched. You should deactivate the plugin.

Mollie for Contact Form 7

Plugin:

Mollie for Contact Form 7

Plugin Slug:
cf7-mollie

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-12165

The vulnerability has not been patched. You should deactivate the plugin.

Charity Addon for Elementor

Plugin:

Charity Addon for Elementor

Plugin Slug:
charity-addon-for-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-12062

The vulnerability has not been patched. You should deactivate the plugin.

Clickbank Storefront

Plugin:

Clickbank Storefront

Plugin Slug:
clickbank-storefront

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-11336

The vulnerability has not been patched. You should deactivate the plugin.

SMS for Lead Capture Forms

Plugin:

SMS for Lead Capture Forms

Plugin Slug:
clicksend-lead-capture-form

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11353

The vulnerability has not been patched. You should deactivate the plugin.

CLUEVO LMS, E-Learning Platform

Plugin:

CLUEVO LMS, E-Learning Platform

Plugin Slug:
cluevo-lms

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11444

The vulnerability has not been patched. You should deactivate the plugin.

Cookielay

Plugin:

Cookielay

Plugin Slug:
cookielay

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-10320

The vulnerability has not been patched. You should deactivate the plugin.

Country Blocker

Plugin:

Country Blocker

Plugin Slug:
country-blocker

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54226

The vulnerability has not been patched. You should deactivate the plugin.

Advanced Element Bucket Addons for Elementor

Plugin:

Advanced Element Bucket Addons for Elementor

Plugin Slug:
cs-element-bucket

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54210

The vulnerability has not been patched. You should deactivate the plugin.

Easy Blocks pro

Plugin:

Easy Blocks pro

Plugin Slug:
easy-blocks-pro

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54256

The vulnerability has not been patched. You should deactivate the plugin.

Easy Code Snippets

Plugin:

Easy Code Snippets

Plugin Slug:
easy-code-snippets

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-11464

The vulnerability has not been patched. You should deactivate the plugin.

Easy Social Feed Premium

Plugin:

Easy Social Feed Premium

Plugin Slug:
easy-facebook-likebox-premium

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-5020

The vulnerability has not been patched. You should deactivate the plugin.

Echoza

Plugin:

Echoza

Plugin Slug:
echoza

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54243

The vulnerability has not been patched. You should deactivate the plugin.

eewee admin custom

Plugin:

eewee admin custom

Plugin Slug:
eewee-admincustom

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54248

The vulnerability has not been patched. You should deactivate the plugin.

Eleblog – Elementor Blog And Magazine Addons

Plugin:

Eleblog – Elementor Blog And Magazine Addons

Plugin Slug:
ele-blog

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-10663

The vulnerability has not been patched. You should deactivate the plugin.

FAQs

Plugin:

FAQs

Plugin Slug:
faqs

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54246

The vulnerability has not been patched. You should deactivate the plugin.

FAT Services Booking

Plugin:

FAT Services Booking

Plugin Slug:
fat-services-booking

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54220

The vulnerability has not been patched. You should deactivate the plugin.

FAT Services Booking

Plugin:

FAT Services Booking

Plugin Slug:
fat-services-booking

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54221

The vulnerability has not been patched. You should deactivate the plugin.

Folder Gallery

Plugin:

Folder Gallery

Plugin Slug:
folder-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11823

The vulnerability has not been patched. You should deactivate the plugin.

Funnelforms Free

Plugin:

Funnelforms Free

Plugin Slug:
funnelforms-free

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-10587

The vulnerability has not been patched. You should deactivate the plugin.

Gold Addons for Elementor

Plugin:

Gold Addons for Elementor

Plugin Slug:
gold-addons-for-elementor

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-12110

The vulnerability has not been patched. You should deactivate the plugin.

Library Management System

Plugin:

Library Management System

Plugin Slug:
library-management-system

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-8679

The vulnerability has not been patched. You should deactivate the plugin.

Contact Form, Survey & Form Builder – MightyForms

Plugin:

Contact Form, Survey & Form Builder – MightyForms

Plugin Slug:
mightyforms

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11897

The vulnerability has not been patched. You should deactivate the plugin.

Gallery

Plugin:

Gallery

Plugin Slug:
multi-gallery

Vulnerability:
PHP Object Injection

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-11501

The vulnerability has not been patched. You should deactivate the plugin.

Login With OTP

Plugin:

Login With OTP

Plugin Slug:
otp-login

Vulnerability:
Broken Authentication

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-11178

The vulnerability has not been patched. You should deactivate the plugin.

Posti Shipping

Plugin:

Posti Shipping

Plugin Slug:
posti-shipping

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-10832

The vulnerability has not been patched. You should deactivate the plugin.

Paloma Widget

Plugin:

Paloma Widget

Plugin Slug:
postman-widget

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54205

The vulnerability has not been patched. You should deactivate the plugin.

Responsive Videos

Plugin:

Responsive Videos

Plugin Slug:
responsive-youtube-videos

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11747

The vulnerability has not been patched. You should deactivate the plugin.

Revy

Plugin:

Revy

Plugin Slug:
revy

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54215

The vulnerability has not been patched. You should deactivate the plugin.

Revy

Plugin:

Revy

Plugin Slug:
revy

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54214

The vulnerability has not been patched. You should deactivate the plugin.

SG Helper

Plugin:

SG Helper

Plugin Slug:
sg-helper

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11093

The vulnerability has not been patched. You should deactivate the plugin.

Simple Ecommerce Shopping Cart

Plugin:

Simple Ecommerce Shopping Cart

Plugin Slug:
simple-e-commerce-shopping-cart

Vulnerability:
Broken Access Control

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-12253

The vulnerability has not been patched. You should deactivate the plugin.

Simple Ecommerce Shopping Cart

Plugin:

Simple Ecommerce Shopping Cart

Plugin Slug:
simple-e-commerce-shopping-cart

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-12128

The vulnerability has not been patched. You should deactivate the plugin.

Smart PopUp Blaster

Plugin:

Smart PopUp Blaster

Plugin Slug:
smart-popup-blaster

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11339

The vulnerability has not been patched. You should deactivate the plugin.

Smoove connector for Elementor forms

Plugin:

Smoove connector for Elementor forms

Plugin Slug:
smoove-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-11367

The vulnerability has not been patched. You should deactivate the plugin.

Splash Sync

Plugin:

Splash Sync

Plugin Slug:
splash-connector

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-11368

The vulnerability has not been patched. You should deactivate the plugin.

SV100 Companion

Plugin:

SV100 Companion

Plugin Slug:
sv100-companion

Vulnerability:
Privilege Escalation

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-54229

The vulnerability has not been patched. You should deactivate the plugin.

TWChat

Plugin:

TWChat

Plugin Slug:
twchat

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-11374

The vulnerability has not been patched. You should deactivate the plugin.

TwentyTwenty

Plugin:

TwentyTwenty

Plugin Slug:
twentytwenty

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11352

The vulnerability has not been patched. You should deactivate the plugin.

Shortcodes Blocks Creator Ultimate

Plugin:

Shortcodes Blocks Creator Ultimate

Plugin Slug:
ultimate-shortcodes-creator

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54264

The vulnerability has not been patched. You should deactivate the plugin.

Unlock Addons for Elementor

Plugin:

Unlock Addons for Elementor

Plugin Slug:
unlock-addons-for-elementor

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54230

The vulnerability has not been patched. You should deactivate the plugin.

Wot Elementor Widgets

Plugin:

Wot Elementor Widgets

Plugin Slug:
wot-elementor-widgets

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54228

The vulnerability has not been patched. You should deactivate the plugin.

WordPress Auction Plugin

Plugin:

WordPress Auction Plugin

Plugin Slug:
wp-auctions

Vulnerability:
SQL Injection

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-51615

The vulnerability has not been patched. You should deactivate the plugin.

WordPress Auction Plugin

Plugin:

WordPress Auction Plugin

Plugin Slug:
wp-auctions

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-54207

The vulnerability has not been patched. You should deactivate the plugin.

WP Media Optimizer

Plugin:

WP Media Optimizer

Plugin Slug:
wp-media-optimizer-webp

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-12060

The vulnerability has not been patched. You should deactivate the plugin.

Mini Program API

Plugin:

Mini Program API

Plugin Slug:
wp-mini-program

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11380

The vulnerability has not been patched. You should deactivate the plugin.

WP Private Content Plus

Plugin:

WP Private Content Plus

Plugin Slug:
wp-private-content-plus

Vulnerability:
Sensitive Data Exposure

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11292

The vulnerability has not been patched. You should deactivate the plugin.

WP System

Plugin:

WP System

Plugin Slug:
wp-system

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-12003

The vulnerability has not been patched. You should deactivate the plugin.

Zooom

Plugin:

Zooom

Plugin Slug:
zooom

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium

CVE:

2024-11451

The vulnerability has not been patched. You should deactivate the plugin.

WooCommerce

Plugin:

WooCommerce

Plugin Slug:
woocommerce

Installations
8,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
9.4.3

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 9.4.3.

WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More

Plugin:

WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More

Plugin Slug:
wpforms-lite

Installations
6,000,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.9.2.2

Severity Score:
High

CVE:

2024-11205

The vulnerability has been patched, so you should update to version 1.9.2.2.

Spectra – WordPress Gutenberg Blocks

Plugin:

Spectra – WordPress Gutenberg Blocks

Plugin Slug:
ultimate-addons-for-gutenberg

Installations
1,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.16.3

Severity Score:
Medium

CVE:

2024-10484

The vulnerability has been patched, so you should update to version 2.16.3.

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Plugin:

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

Plugin Slug:
fluentform

Installations
500,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.1

Severity Score:
Medium

CVE:

2024-9651

The vulnerability has been patched, so you should update to version 5.2.1.

Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery

Plugin:

Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery

Plugin Slug:
nextgen-gallery

Installations
400,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.59.5

Severity Score:
Medium

CVE:

2024-5020

The vulnerability has been patched, so you should update to version 3.59.5.

Firelight Lightbox

Plugin:

Firelight Lightbox

Plugin Slug:
easy-fancybox

Installations
200,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.4

Severity Score:
Medium

CVE:

2024-5020

The vulnerability has been patched, so you should update to version 2.3.4.

FileBird – WordPress Media Library Folders & File Manager

Plugin:

FileBird – WordPress Media Library Folders & File Manager

Plugin Slug:
filebird

Installations
200,000+

Vulnerability:
Broken Access Control

Patched in Version:
6.3.4

Severity Score:
Medium

CVE:

2024-53825

The vulnerability has been patched, so you should update to version 6.3.4.

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows)

Plugin:

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows)

Plugin Slug:
bdthemes-element-pack-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.10.6

Severity Score:
Medium

CVE:

2024-9058

The vulnerability has been patched, so you should update to version 5.10.6.

Beaver Builder – WordPress Page Builder

Plugin:

Beaver Builder – WordPress Page Builder

Plugin Slug:
beaver-builder-lite-version

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.4.4

Severity Score:
Medium

CVE:

2024-53797

The vulnerability has been patched, so you should update to version 2.8.4.4.

Colibri Page Builder

Plugin:

Colibri Page Builder

Plugin Slug:
colibri-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.288

Severity Score:
Medium

CVE:

2024-5020

The vulnerability has been patched, so you should update to version 1.0.288.

Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel

Plugin:

Slider & Popup Builder by Depicter – Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel

Plugin Slug:
depicter

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.2

Severity Score:
Medium

CVE:

2024-4633

The vulnerability has been patched, so you should update to version 3.2.2.

Gallery Plugin for WordPress – Envira Photo Gallery

Plugin:

Gallery Plugin for WordPress – Envira Photo Gallery

Plugin Slug:
envira-gallery-lite

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8.16

Severity Score:
Medium

CVE:

2024-5020

The vulnerability has been patched, so you should update to version 1.8.16.

Advanced File Manager

Plugin:

Advanced File Manager

Plugin Slug:
file-manager-advanced

Installations
100,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
5.2.11

Severity Score:
High

CVE:

2024-11391

The vulnerability has been patched, so you should update to version 5.2.11.

FileOrganizer – Manage WordPress and Website Files

Plugin:

FileOrganizer – Manage WordPress and Website Files

Plugin Slug:
fileorganizer

Installations
100,000+

Vulnerability:
Path Traversal

Patched in Version:
1.1.5

Severity Score:
High

CVE:

2024-11010

The vulnerability has been patched, so you should update to version 1.1.5.

Responsive Lightbox & Gallery

Plugin:

Responsive Lightbox & Gallery

Plugin Slug:
responsive-lightbox

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.9

Severity Score:
Medium

CVE:

2024-5020

The vulnerability has been patched, so you should update to version 2.4.9.

The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce

Plugin:

The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce

Plugin Slug:
the-plus-addons-for-elementor-page-builder

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.0.1

Severity Score:
Medium

CVE:

2024-53823

The vulnerability has been patched, so you should update to version 6.0.1.

TI WooCommerce Wishlist

Plugin:

TI WooCommerce Wishlist

Plugin Slug:
ti-woocommerce-wishlist

Installations
100,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.9.2

Severity Score:
High

CVE:

2024-10567

The vulnerability has been patched, so you should update to version 2.9.2.

AnyWhere Elementor

Plugin:

AnyWhere Elementor

Plugin Slug:
anywhere-elementor

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.2.12

Severity Score:
Medium

CVE:

2024-10777

The vulnerability has been patched, so you should update to version 1.2.12.

PowerPack Elementor Addons (Free Widgets, Extensions and Templates)

Plugin:

PowerPack Elementor Addons (Free Widgets, Extensions and Templates)

Plugin Slug:
powerpack-lite-for-elementor

Installations
90,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.8.2

Severity Score:
Medium

CVE:

2024-10692

The vulnerability has been patched, so you should update to version 2.8.2.

WPC Smart Quick View for WooCommerce

Plugin:

WPC Smart Quick View for WooCommerce

Plugin Slug:
woo-smart-quick-view

Installations
80,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.2

Severity Score:
Medium

CVE:

2024-5020

The vulnerability has been patched, so you should update to version 4.1.2.

WP Hide & Security Enhancer

Plugin:

WP Hide & Security Enhancer

Plugin Slug:
wp-hide-security-enhancer

Installations
70,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.5.2

Severity Score:
High

CVE:

2024-11585

The vulnerability has been patched, so you should update to version 2.5.2.

Getwid – Gutenberg Blocks

Plugin:

Getwid – Gutenberg Blocks

Plugin Slug:
getwid

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.12

Severity Score:
Medium

CVE:

2024-5020

The vulnerability has been patched, so you should update to version 2.0.12.

If Menu – Visibility control for Menus

Plugin:

If Menu – Visibility control for Menus

Plugin Slug:
if-menu

Installations
60,000+

Vulnerability:
Broken Access Control

Patched in Version:
0.19.2

Severity Score:
Medium

CVE:

2024-7894

The vulnerability has been patched, so you should update to version 0.19.2.

Visual Portfolio, Photo Gallery & Post Grid

Plugin:

Visual Portfolio, Photo Gallery & Post Grid

Plugin Slug:
visual-portfolio

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.10

Severity Score:
Medium

CVE:

2024-5020

The vulnerability has been patched, so you should update to version 3.3.10.

Carousel, Slider, Gallery by WP Carousel – Image Carousel with Lightbox & Photo Gallery, Video Slider, Post Carousel & Post Grid, Product Carousel & Product Grid

Plugin:

Carousel, Slider, Gallery by WP Carousel – Image Carousel with Lightbox & Photo Gallery, Video Slider, Post Carousel & Post Grid, Product Carousel & Product Grid

Plugin Slug:
wp-carousel-free

Installations
60,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.6.9

Severity Score:
Medium

CVE:

2024-5020

The vulnerability has been patched, so you should update to version 2.6.9.

Bold Page Builder

Plugin:

Bold Page Builder

Plugin Slug:
bold-page-builder

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.2

Severity Score:
Medium

CVE:

2024-53801

The vulnerability has been patched, so you should update to version 5.2.2.

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Plugin:

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder

Plugin Slug:
form-maker

Installations
50,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.15.28

Severity Score:
Medium

CVE:

2024-5020

The vulnerability has been patched, so you should update to version 1.15.28.

FancyBox for WordPress

Plugin:

FancyBox for WordPress

Plugin Slug:
fancybox-for-wordpress

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.3.5

Severity Score:
Medium

CVE:

2024-5020

The vulnerability has been patched, so you should update to version 3.3.5.

Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor

Plugin:

Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor

Plugin Slug:
gutentor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.4.0

Severity Score:
Medium

CVE:

2024-10178

The vulnerability has been patched, so you should update to version 3.4.0.

Themesflat Addons For Elementor

Plugin:

Themesflat Addons For Elementor

Plugin Slug:
themesflat-addons-for-elementor

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.3

Severity Score:
Medium

CVE:

2024-53796

The vulnerability has been patched, so you should update to version 2.2.3.

Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX

Plugin:

Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX

Plugin Slug:
ultimate-post

Installations
40,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.1.16

Severity Score:
Medium

CVE:

2024-53818

The vulnerability has been patched, so you should update to version 4.1.16.

Tutor LMS Elementor Addons

Plugin:

Tutor LMS Elementor Addons

Plugin Slug:
tutor-lms-elementor-addons

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.6

Severity Score:
Medium

CVE:

2024-53816

The vulnerability has been patched, so you should update to version 2.1.6.

Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy)

Plugin:

Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy)

Plugin Slug:
wp-analytify

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.5.0

Severity Score:
Medium

CVE:

2024-53814

The vulnerability has been patched, so you should update to version 5.5.0.

WP Umbrella: Update Backup Restore & Monitoring

Plugin:

WP Umbrella: Update Backup Restore & Monitoring

Plugin Slug:
wp-health

Installations
30,000+

Vulnerability:
Local File Inclusion

Patched in Version:
2.17.1

Severity Score:
Critical

CVE:

2024-12209

The vulnerability has been patched, so you should update to version 2.17.1.

Maspik – Advanced Spam Protection

Plugin:

Maspik – Advanced Spam Protection

Plugin Slug:
contact-forms-anti-spam

Installations
20,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.2.8

Severity Score:
Medium

CVE:

2024-53806

The vulnerability has been patched, so you should update to version 2.2.8.

Futurio Extra

Plugin:

Futurio Extra

Plugin Slug:
futurio-extra

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.15

Severity Score:
Medium

CVE:

2024-53802

The vulnerability has been patched, so you should update to version 2.0.15.

FV Flowplayer Video Player

Plugin:

FV Flowplayer Video Player

Plugin Slug:
fv-wordpress-flowplayer

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
7.5.48.7212

Severity Score:
Medium

CVE:

2024-5020

The vulnerability has been patched, so you should update to version 7.5.48.7212.

Product Labels For Woocommerce (Sale Badges)

Plugin:

Product Labels For Woocommerce (Sale Badges)

Plugin Slug:
aco-product-labels-for-woocommerce

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
1.5.9

Severity Score:
High

CVE:

2024-53817

The vulnerability has been patched, so you should update to version 1.5.9.

Video Gallery – YouTube Gallery and Vimeo Gallery

Plugin:

Video Gallery – YouTube Gallery and Vimeo Gallery

Plugin Slug:
gallery-videos

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
2.4.3

Severity Score:
High

CVE:

2024-10247

The vulnerability has been patched, so you should update to version 2.4.3.

Video Gallery – YouTube Gallery and Vimeo Gallery

Plugin:

Video Gallery – YouTube Gallery and Vimeo Gallery

Plugin Slug:
gallery-videos

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.2

Severity Score:
Medium

CVE:

2024-9769

The vulnerability has been patched, so you should update to version 2.4.2.

LA-Studio Element Kit for Elementor

Plugin:

LA-Studio Element Kit for Elementor

Plugin Slug:
lastudio-element-kit

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.4.5

Severity Score:
Medium

CVE:

2024-10787

The vulnerability has been patched, so you should update to version 1.4.5.

myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program.

Plugin:

myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program.

Plugin Slug:
mycred

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.6

Severity Score:
Medium

CVE:

2024-11201

The vulnerability has been patched, so you should update to version 2.7.6.

NEX-Forms – Ultimate Form Builder – Contact forms and much more

Plugin:

NEX-Forms – Ultimate Form Builder – Contact forms and much more

Plugin Slug:
nex-forms-express-wp-form-builder

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
8.7.9

Severity Score:
High

CVE:

2024-53808

The vulnerability has been patched, so you should update to version 8.7.9.

Simple Side Tab

Plugin:

Simple Side Tab

Plugin Slug:
simple-side-tab

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.0

Severity Score:
Medium

CVE:

2024-11183

The vulnerability has been patched, so you should update to version 2.2.0.

Swift Performance Lite

Plugin:

Swift Performance Lite

Plugin Slug:
swift-performance-lite

Installations
10,000+

Vulnerability:
Path Traversal

Patched in Version:
2.3.7.2

Severity Score:
High

CVE:

2024-10516

The vulnerability has been patched, so you should update to version 2.3.7.2.

ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

Plugin:

ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup

Plugin Slug:
armember-membership

Installations
9,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
4.0.52

Severity Score:
Medium

CVE:

2024-10681

The vulnerability has been patched, so you should update to version 4.0.52.

Pojo Forms

Plugin:

Pojo Forms

Plugin Slug:
pojo-forms

Installations
7,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
1.4.8

Severity Score:
Medium

CVE:

2024-10909

The vulnerability has been patched, so you should update to version 1.4.8.

Poll Maker – Versus Polls, Anonymous Polls, Image Polls

Plugin:

Poll Maker – Versus Polls, Anonymous Polls, Image Polls

Plugin Slug:
poll-maker

Installations
7,000+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.5.5

Severity Score:
Medium

CVE:

2024-12115

The vulnerability has been patched, so you should update to version 5.5.5.

WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder

Plugin:

WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder

Plugin Slug:
wdesignkit

Installations
7,000+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.1.0

Severity Score:
Medium

CVE:

2024-53811

The vulnerability has been patched, so you should update to version 1.1.0.

Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins

Plugin:

Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins

Plugin Slug:
related-post

Installations
5,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
2.0.59

Severity Score:
Medium

CVE:

2024-10937

The vulnerability has been patched, so you should update to version 2.0.59.

WP Travel – Ultimate Travel Booking System, Tour Management Engine

Plugin:

WP Travel – Ultimate Travel Booking System, Tour Management Engine

Plugin Slug:
wp-travel

Installations
5,000+

Vulnerability:
Broken Access Control

Patched in Version:
9.7.0

Severity Score:
Medium

CVE:

2024-53813

The vulnerability has been patched, so you should update to version 9.7.0.

All Bootstrap Blocks

Plugin:

All Bootstrap Blocks

Plugin Slug:
all-bootstrap-blocks

Installations
4,000+

Vulnerability:
Local File Inclusion

Patched in Version:
1.3.20

Severity Score:
High

CVE:

2024-53824

The vulnerability has been patched, so you should update to version 1.3.20.

Arkhe Blocks

Plugin:

Arkhe Blocks

Plugin Slug:
arkhe-blocks

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.27.1

Severity Score:
Medium

CVE:

2024-53794

The vulnerability has been patched, so you should update to version 2.27.1.

Pinpoint Booking System – #1 WordPress Booking Plugin

Plugin:

Pinpoint Booking System – #1 WordPress Booking Plugin

Plugin Slug:
booking-system

Installations
4,000+

Vulnerability:
SQL Injection

Patched in Version:
2.9.9.5.2

Severity Score:
High

CVE:

2024-53815

The vulnerability has been patched, so you should update to version 2.9.9.5.2.

ElementsReady Addons for Elementor

Plugin:

ElementsReady Addons for Elementor

Plugin Slug:
element-ready-lite

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.4.8

Severity Score:
Medium

CVE:

2024-54224

The vulnerability has been patched, so you should update to version 6.4.8.

Contact Form, Survey, Quiz & Popup Form Builder – ARForms

Plugin:

Contact Form, Survey, Quiz & Popup Form Builder – ARForms

Plugin Slug:
arforms-form-builder

Installations
3,000+

Vulnerability:
Content Injection

Patched in Version:
1.7.2

Severity Score:
Medium

CVE:

2024-54223

The vulnerability has been patched, so you should update to version 1.7.2.

WP Job Manager – Company Profiles

Plugin:

WP Job Manager – Company Profiles

Plugin Slug:
wp-job-manager-companies

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.8

Severity Score:
High

CVE:

2023-6978

The vulnerability has been patched, so you should update to version 1.8.

Accordion Slider

Plugin:

Accordion Slider

Plugin Slug:
accordion-slider

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.13

Severity Score:
Medium

CVE:

2024-5020

The vulnerability has been patched, so you should update to version 1.9.13.

Knowledge Base documentation & wiki plugin – BasePress Docs

Plugin:

Knowledge Base documentation & wiki plugin – BasePress Docs

Plugin Slug:
basepress

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.16.3.4

Severity Score:
Medium

CVE:

2024-10664

The vulnerability has been patched, so you should update to version 2.16.3.4.

Message Filter for Contact Form 7

Plugin:

Message Filter for Contact Form 7

Plugin Slug:
cf7-message-filter

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.6.3

Severity Score:
Medium

CVE:

2024-54254

The vulnerability has been patched, so you should update to version 1.6.3.

KiviCare – Clinic & Patient Management System (EHR)

Plugin:

KiviCare – Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
3.6.5

Severity Score:
High

CVE:

2024-11730

The vulnerability has been patched, so you should update to version 3.6.5.

KiviCare – Clinic & Patient Management System (EHR)

Plugin:

KiviCare – Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
3.6.5

Severity Score:
High

CVE:

2024-11729

The vulnerability has been patched, so you should update to version 3.6.5.

KiviCare – Clinic & Patient Management System (EHR)

Plugin:

KiviCare – Clinic & Patient Management System (EHR)

Plugin Slug:
kivicare-clinic-management-system

Installations
2,000+

Vulnerability:
SQL Injection

Patched in Version:
3.6.5

Severity Score:
Critical

CVE:

2024-11728

The vulnerability has been patched, so you should update to version 3.6.5.

Online Booking & Scheduling Calendar for WordPress by vcita

Plugin:

Online Booking & Scheduling Calendar for WordPress by vcita

Plugin Slug:
meeting-scheduler-by-vcita

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.5.2

Severity Score:
Medium

CVE:

2024-9872

The vulnerability has been patched, so you should update to version 4.5.2.

Plugin Check (PCP)

Plugin:

Plugin Check (PCP)

Plugin Slug:
plugin-check

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.1

Severity Score:
Medium

The vulnerability has been patched, so you should update to version 1.3.1.

Active Products Tables for WooCommerce. Use constructor to create tables 

Plugin:

Active Products Tables for WooCommerce. Use constructor to create tables 

Plugin Slug:
profit-products-tables-for-woocommerce

Installations
2,000+

Vulnerability:
Arbitrary Code Execution

Patched in Version:
1.0.6.6

Severity Score:
High

CVE:

2024-10959

The vulnerability has been patched, so you should update to version 1.0.6.6.

Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress

Plugin:

Client Invoicing by Sprout Invoices – Easy Estimates and Invoices for WordPress

Plugin Slug:
sprout-invoices

Installations
2,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
20.8.1

Severity Score:
Medium

CVE:

2024-53819

The vulnerability has been patched, so you should update to version 20.8.1.

Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials

Plugin:

Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials

Plugin Slug:
stars-testimonials-with-slider-and-masonry-grid

Installations
2,000+

Vulnerability:
Local File Inclusion

Patched in Version:
3.3.4

Severity Score:
High

CVE:

2024-11429

The vulnerability has been patched, so you should update to version 3.3.4.

WPBITS Addons For Elementor Page Builder

Plugin:

WPBITS Addons For Elementor Page Builder

Plugin Slug:
wpbits-addons-for-elementor

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6

Severity Score:
Medium

CVE:

2024-8962

The vulnerability has been patched, so you should update to version 1.6.

XLTab – Accordions and Tabs for Elementor Page Builder

Plugin:

XLTab – Accordions and Tabs for Elementor Page Builder

Plugin Slug:
xl-tab

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.5

Severity Score:
Medium

CVE:

2024-10689

The vulnerability has been patched, so you should update to version 1.5.

Captivate Sync

Plugin:

Captivate Sync

Plugin Slug:
captivatesync-trade

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.26

Severity Score:
Medium

CVE:

2024-53820

The vulnerability has been patched, so you should update to version 2.0.26.

Contact Form Builder by vcita

Plugin:

Contact Form Builder by vcita

Plugin Slug:
contact-form-with-a-meeting-scheduler-by-vcita

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.10.5

Severity Score:
Medium

CVE:

2024-10056

The vulnerability has been patched, so you should update to version 4.10.5.

Event Tickets with Ticket Scanner

Plugin:

Event Tickets with Ticket Scanner

Plugin Slug:
event-tickets-with-ticket-scanner

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.4

Severity Score:
Medium

CVE:

2024-9866

The vulnerability has been patched, so you should update to version 2.4.4.

Listdom – Business Directory and Classified Ads Listings WordPress Plugin

Plugin:

Listdom – Business Directory and Classified Ads Listings WordPress Plugin

Plugin Slug:
listdom

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.7.1

Severity Score:
Medium

CVE:

2024-11854

The vulnerability has been patched, so you should update to version 3.7.1.

????? ?? ???? – ???? ?? ????

Plugin:

????? ?? ???? – ???? ?? ????

Plugin Slug:
pgall-for-woocommerce

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.3

Severity Score:
High

CVE:

2024-11943

The vulnerability has been patched, so you should update to version 5.2.3.

SearchIQ – The Search Solution

Plugin:

SearchIQ – The Search Solution

Plugin Slug:
searchiq

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.7

Severity Score:
Medium

CVE:

2024-10885

The vulnerability has been patched, so you should update to version 4.7.

Simple Restrict

Plugin:

Simple Restrict

Plugin Slug:
simple-restrict

Installations
1,000+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.2.8

Severity Score:
Medium

CVE:

2024-11106

The vulnerability has been patched, so you should update to version 1.2.8.

Broadcast

Plugin:

Broadcast

Plugin Slug:
threewp-broadcast

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
51.02

Severity Score:
High

CVE:

2024-11379

The vulnerability has been patched, so you should update to version 51.02.

WPCasa

Plugin:

WPCasa

Plugin Slug:
wpcasa

Installations
1,000+

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
1.3.0

Severity Score:
Medium

CVE:

2024-53826

The vulnerability has been patched, so you should update to version 1.3.0.

Church Admin

Plugin:

Church Admin

Plugin Slug:
church-admin

Installations
900+

Vulnerability:
Broken Access Control

Patched in Version:
5.0.9

Severity Score:
Medium

CVE:

2024-53795

The vulnerability has been patched, so you should update to version 5.0.9.

3DPrint Lite

Plugin:

3DPrint Lite

Plugin Slug:
3dprint-lite

Installations
800+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.1

Severity Score:
Medium

CVE:

2024-10480

The vulnerability has been patched, so you should update to version 2.1.

Email Address Obfuscation

Plugin:

Email Address Obfuscation

Plugin Slug:
email-address-obfuscation

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.0

Severity Score:
Medium

CVE:

2024-11935

The vulnerability has been patched, so you should update to version 1.1.0.

Property Hive Mortgage Calculator

Plugin:

Property Hive Mortgage Calculator

Plugin Slug:
property-hive-mortgage-calculator

Installations
800+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.7

Severity Score:
Medium

CVE:

2024-11940

The vulnerability has been patched, so you should update to version 1.0.7.

Quran multilanguage Text & Audio

Plugin:

Quran multilanguage Text & Audio

Plugin Slug:
quran-text-multilanguage

Installations
700+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.22

Severity Score:
High

CVE:

2024-11973

The vulnerability has been patched, so you should update to version 2.3.22.

jAlbum Bridge

Plugin:

jAlbum Bridge

Plugin Slug:
jalbum-bridge

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.16

Severity Score:
Medium

CVE:

2024-11853

The vulnerability has been patched, so you should update to version 2.0.16.

My auctions allegro

Plugin:

My auctions allegro

Plugin Slug:
my-auctions-allegro-free-edition

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.6.18

Severity Score:
High

CVE:

2024-11707

The vulnerability has been patched, so you should update to version 3.6.18.

Additional Custom Order Status for WooCommerce

Plugin:

Additional Custom Order Status for WooCommerce

Plugin Slug:
order-status-for-woocommerce

Installations
600+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.1

Severity Score:
High

CVE:

2024-11814

The vulnerability has been patched, so you should update to version 1.6.1.

Accounting for WooCommerce

Plugin:

Accounting for WooCommerce

Plugin Slug:
accounting-for-woocommerce

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.6.7

Severity Score:
High

CVE:

2024-11324

The vulnerability has been patched, so you should update to version 1.6.7.

AWeber Forms by Optin Cat

Plugin:

AWeber Forms by Optin Cat

Plugin Slug:
aweber-wp

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.8

Severity Score:
High

CVE:

2024-11325

The vulnerability has been patched, so you should update to version 2.5.8.

iChart – Easy Charts and Graphs

Plugin:

iChart – Easy Charts and Graphs

Plugin Slug:
ichart

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.4

Severity Score:
Medium

CVE:

2024-11928

The vulnerability has been patched, so you should update to version 2.1.4.

???? ???

Plugin:

???? ???

Plugin Slug:
mshop-naver-talktalk

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.1

Severity Score:
Medium

CVE:

2024-11904

The vulnerability has been patched, so you should update to version 1.2.1.

Namaste! LMS

Plugin:

Namaste! LMS

Plugin Slug:
namaste-lms

Installations
500+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
2.6.5

Severity Score:
Medium

CVE:

2024-53809

The vulnerability has been patched, so you should update to version 2.6.5.

Flower Delivery by Florist One

Plugin:

Flower Delivery by Florist One

Plugin Slug:
flower-delivery-by-florist-one

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.9.1

Severity Score:
Medium

CVE:

2024-11769

The vulnerability has been patched, so you should update to version 3.9.1.

WIP WooCarousel Lite

Plugin:

WIP WooCarousel Lite

Plugin Slug:
wip-woocarousel-lite

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.7

Severity Score:
Medium

CVE:

2024-11779

The vulnerability has been patched, so you should update to version 1.1.7.

WP eCards

Plugin:

WP eCards

Plugin Slug:
wp-ecards-invites

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.905

Severity Score:
Medium

CVE:

2024-11903

The vulnerability has been patched, so you should update to version 1.3.905.

WP Mailster

Plugin:

WP Mailster

Plugin Slug:
wp-mailster

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
1.8.17.0

Severity Score:
Medium

CVE:

2024-53803

The vulnerability has been patched, so you should update to version 1.8.17.0.

WP Mailster

Plugin:

WP Mailster

Plugin Slug:
wp-mailster

Installations
400+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
1.8.17.0

Severity Score:
High

CVE:

2024-53804

The vulnerability has been patched, so you should update to version 1.8.17.0.

WP Mailster

Plugin:

WP Mailster

Plugin Slug:
wp-mailster

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
1.8.17.0

Severity Score:
High

CVE:

2024-53805

The vulnerability has been patched, so you should update to version 1.8.17.0.

WP Mailster

Plugin:

WP Mailster

Plugin Slug:
wp-mailster

Installations
400+

Vulnerability:
SQL Injection

Patched in Version:
1.8.17.0

Severity Score:
High

CVE:

2024-53807

The vulnerability has been patched, so you should update to version 1.8.17.0.

Simple User Registration

Plugin:

Simple User Registration

Plugin Slug:
wp-registration

Installations
400+

Vulnerability:
Broken Access Control

Patched in Version:
6.0

Severity Score:
Critical

CVE:

2024-53810

The vulnerability has been patched, so you should update to version 6.0.

Campaign Monitor Forms by Optin Cat

Plugin:

Campaign Monitor Forms by Optin Cat

Plugin Slug:
campaign-monitor-wp

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.5.8

Severity Score:
High

CVE:

2024-11326

The vulnerability has been patched, so you should update to version 2.5.8.

CardGate Payments for WooCommerce

Plugin:

CardGate Payments for WooCommerce

Plugin Slug:
cardgate

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.2.2

Severity Score:
High

CVE:

2024-12257

The vulnerability has been patched, so you should update to version 3.2.2.

Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more

Plugin:

Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more

Plugin Slug:
scratch-win-giveaways-for-website-facebook

Installations
300+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.7.0

Severity Score:
Medium

CVE:

2024-11898

The vulnerability has been patched, so you should update to version 2.7.0.

Simple Redirection

Plugin:

Simple Redirection

Plugin Slug:
eelv-redirection

Installations
200+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.5.1

Severity Score:
Medium

CVE:

2024-11341

The vulnerability has been patched, so you should update to version 1.5.1.

Email Reminders

Plugin:

Email Reminders

Plugin Slug:
email-reminders

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.5

Severity Score:
Medium

CVE:

2024-11945

The vulnerability has been patched, so you should update to version 2.0.5.

Form Data Collector

Plugin:

Form Data Collector

Plugin Slug:
form-data-collector

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.4

Severity Score:
High

CVE:

2024-11461

The vulnerability has been patched, so you should update to version 2.2.4.

Next-Cart Store to WooCommerce Migration

Plugin:

Next-Cart Store to WooCommerce Migration

Plugin Slug:
nextcart-woocommerce-migration

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.9.4

Severity Score:
High

CVE:

2024-11687

The vulnerability has been patched, so you should update to version 3.9.4.

WP GeoNames

Plugin:

WP GeoNames

Plugin Slug:
wp-geonames

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9

Severity Score:
High

CVE:

2024-53812

The vulnerability has been patched, so you should update to version 1.9.

B Testimonial – Testimonial plugin for WP

Plugin:

B Testimonial – Testimonial plugin for WP

Plugin Slug:
b-testimonial

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.3

Severity Score:
Medium

CVE:

2024-11880

The vulnerability has been patched, so you should update to version 1.2.3.

ONLYOFFICE Docs

Plugin:

ONLYOFFICE Docs

Plugin Slug:
onlyoffice

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2.0

Severity Score:
Medium

CVE:

2024-11450

The vulnerability has been patched, so you should update to version 2.2.0.

Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more!

Plugin:

Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more!

Plugin Slug:
pie-forms-for-wp

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5

Severity Score:
High

CVE:

2024-11436

The vulnerability has been patched, so you should update to version 1.5.

Prodigy Commerce

Plugin:

Prodigy Commerce

Plugin Slug:
prodigy-commerce

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.0.9

Severity Score:
Medium

CVE:

2024-54250

The vulnerability has been patched, so you should update to version 3.0.9.

NPS computy

Plugin:

NPS computy

Plugin Slug:
nps-computy

Installations
90+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.8.1

Severity Score:
High

CVE:

2024-11807

The vulnerability has been patched, so you should update to version 2.8.1.

Verowa Connect

Plugin:

Verowa Connect

Plugin Slug:
verowa-connect

Installations
90+

Vulnerability:
SQL Injection

Patched in Version:
3.0.2

Severity Score:
Critical

CVE:

2024-11460

The vulnerability has been patched, so you should update to version 3.0.2.

Dollie Hub – Build Your Own WordPress Cloud Platform

Plugin:

Dollie Hub – Build Your Own WordPress Cloud Platform

Plugin Slug:
dollie

Installations
80+

Vulnerability:
Broken Access Control

Patched in Version:
6.2.1

Severity Score:
Medium

CVE:

2024-12099

The vulnerability has been patched, so you should update to version 6.2.1.

Z-Downloads

Plugin:

Z-Downloads

Plugin Slug:
z-downloads

Installations
50+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.11.8

Severity Score:
Medium

CVE:

2024-54206

The vulnerability has been patched, so you should update to version 1.11.8.

BMLT Tabbed Map

Plugin:

BMLT Tabbed Map

Plugin Slug:
bmlt-tabbed-map

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.0

Severity Score:
Medium

CVE:

2024-11866

The vulnerability has been patched, so you should update to version 1.2.0.

Quick License Manager – WooCommerce Plugin

Plugin:

Quick License Manager – WooCommerce Plugin

Plugin Slug:
quick-license-manager

Installations
40+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.18

Severity Score:
High

CVE:

2024-11805

The vulnerability has been patched, so you should update to version 2.4.18.

FloristPress – Customize your Woo store for your Florist

Plugin:

FloristPress – Customize your Woo store for your Florist

Plugin Slug:
bakkbone-florist-companion

Installations
10+

Vulnerability:
Sensitive Data Exposure

Patched in Version:
7.4.0

Severity Score:
Medium

CVE:

2024-53799

The vulnerability has been patched, so you should update to version 7.4.0.

FloristPress – Customize your Woo store for your Florist

Plugin:

FloristPress – Customize your Woo store for your Florist

Plugin Slug:
bakkbone-florist-companion

Installations
10+

Vulnerability:
Arbitrary Content Deletion

Patched in Version:
7.4.0

Severity Score:
Medium

CVE:

2024-53798

The vulnerability has been patched, so you should update to version 7.4.0.

CMSMasters Elementor Addon

Plugin:

CMSMasters Elementor Addon

Plugin Slug:
cmsmasters-elementor-addon

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.15.0

Severity Score:
Medium

CVE:

2024-9694

The vulnerability has been patched, so you should update to version 1.15.0.

Eyewear prescription form

Plugin:

Eyewear prescription form

Plugin Slug:
eyewear-prescription-form

Vulnerability:
Privilege Escalation

Patched in Version:
4.0.19

Severity Score:
Critical

CVE:

2024-54239

The vulnerability has been patched, so you should update to version 4.0.19.

FooGallery Premium

Plugin:

FooGallery Premium

Plugin Slug:
foogallery-premium

Vulnerability:
Directory Traversal

Patched in Version:
2.4.27

Severity Score:
High

CVE:

2023-6947

The vulnerability has been patched, so you should update to version 2.4.27.

Goodlayers Core

Plugin:

Goodlayers Core

Plugin Slug:
goodlayers-core

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.8

Severity Score:
High

CVE:

2024-11200

The vulnerability has been patched, so you should update to version 2.0.8.

Luna Web Radio Player

Plugin:

Luna Web Radio Player

Plugin Slug:
lu-radioplayer

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
6.24.11.15

Severity Score:
Medium

CVE:

2024-10881

The vulnerability has been patched, so you should update to version 6.24.11.15.

Pie Register Premium

Plugin:

Pie Register Premium

Plugin Slug:
pie-register-premium

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.8.3.3

Severity Score:
High

CVE:

2024-53821

The vulnerability has been patched, so you should update to version 3.8.3.3.

Pie Register Premium

Plugin:

Pie Register Premium

Plugin Slug:
pie-register-premium

Vulnerability:
Arbitrary File Upload

Patched in Version:
3.8.3.3

Severity Score:
Critical

CVE:

2024-53822

The vulnerability has been patched, so you should update to version 3.8.3.3.

Pie Register (Add on) – Social Sites Login

Plugin:

Pie Register (Add on) – Social Sites Login

Plugin Slug:
pie-register-social-site

Vulnerability:
Broken Authentication

Patched in Version:
1.8

Severity Score:
High

CVE:

2024-11293

The vulnerability has been patched, so you should update to version 1.8.

WordPress Themes — 6 Patched / 3 Unpatched

Gaga Lite

Theme:

Gaga Lite

Theme Slug:
gaga-lite

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-52488

The vulnerability has not been patched. You should switch themes.

One Paze

Theme:

One Paze

Theme Slug:
one-paze

Vulnerability:
Arbitrary File Upload

Patched in Version:
No Fix

Severity Score:
Critical

CVE:

2024-52488

The vulnerability has not been patched. You should switch themes.

tydskrif

Theme:

tydskrif

Theme Slug:
tydskrif

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High

CVE:

2024-54257

The vulnerability has not been patched. You should switch themes.

Blocksy

Theme:

Blocksy

Theme Slug:
blocksy

Downloads
3,976,858

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.78

Severity Score:
Medium

CVE:

2024-11420

The vulnerability has been patched, so you should update to version 2.0.78.

Flixita

Theme:

Flixita

Theme Slug:
flixita

Downloads
110,003

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.83

Severity Score:
High

CVE:

2024-10836

The vulnerability has been patched, so you should update to version 1.0.83.

NewsMunch

Theme:

NewsMunch

Theme Slug:
newsmunch

Downloads
60,837

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.0.36

Severity Score:
Medium

CVE:

2024-10848

The vulnerability has been patched, so you should update to version 1.0.36.

Pubnews

Theme:

Pubnews

Theme Slug:
pubnews

Downloads
12,310

Vulnerability:
Broken Access Control

Patched in Version:
1.0.8

Severity Score:
High

CVE:

2024-10578

The vulnerability has been patched, so you should update to version 1.0.8.

Soledad

Theme:

Soledad

Theme Slug:
soledad

Vulnerability:
Local File Inclusion

Patched in Version:
8.6.0

Severity Score:
High

CVE:

2024-11289

The vulnerability has been patched, so you should update to version 8.6.0.

Sweet Date

Theme:

Sweet Date

Theme Slug:
sweetdate

Vulnerability:
Privilege Escalation

Patched in Version:
3.8.0

Severity Score:
Critical

CVE:

2024-43222

The vulnerability has been patched, so you should update to version 3.8.0.

window[“e5233563_db64_4dd4_bf41_df19623a472c”] = {“blockId”:”e5233563-db64-4dd4-bf41-df19623a472c”,”className”:””,”heading”:”Solid Security is part of Solid Suite \u2014 The best foundation for WordPress websites.”,”text”:”Every WordPress site needs security, backups, and management tools. That\u2019s Solid Suite \u2014 an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy\u2019s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!”,”buttonText”:”Get Solid Security”,”buttonLink”:”\/pricing”,”buttonTarget”:”_self”,”buttonRel”:””};

Solid Security is part of Solid Suite — The best foundation for WordPress websites.

Every WordPress site needs security, backups, and management tools. That’s Solid Suite — an integrated bundle of three plugins: Solid Security, Solid Backups, and Solid Central. You also get access to Solid Academy’s learning resources for WordPress professionals. Build your next WordPress website on a solid foundation with Solid Suite!

Get Solid Security

The post WordPress Vulnerability Report — December 11, 2024 appeared first on SolidWP.

Source link

Written by:
Abdul Wahid
Published on:
December 30, 2024

Categories: Woocommerce

Primary Sidebar

Wordpress

  • Content Management Systems (2)
  • Digital Marketing (4)
  • Internet Marketing (28)
  • Latest News (458)
  • Online Business (2)
  • Plugins (519)
  • Themes (521)
  • Videos (1,350)
  • Website Development (1)
  • Woocommerce (589)
  • WordPress (6)

Recent Articles

Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential with WordPress: Tips, Tools, and Strategies

Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential: Harnessing the Power of WordPress

Search our site

Explore more

Get our Wordpress Guide Get Plugins Get Connected

Footer

VirusWord by Promaps, Inc.

Barnes Place
Colombo 7, Western 00700

Copyright © 2025 · Promaps, Inc.

Keep In Touch

  • Email
  • Facebook
  • Instagram
  • Pinterest
  • Twitter